Thehackernews
Critical Check Point SmartConsole Vulnerability Under Active Exploitation
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Check Point has confirmed a critical authentication bypass vulnerability, CVE-2026-16232, in its SmartConsole management tool, allowing unauthenticated attackers to gain full admin privileges. This vulnerability is actively being exploited in the wild, affecting a small number of customers with specific configurations that expose the Management Server to the internet without IP restrictions. The CVSS score for this vulnerability is 9.3, indicating its severity. Check Point has released patches and advised users to limit access to trusted IP addresses. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating a patch deadline of July 25, 2026. The vulnerability was first identified during a routine internal review, with evidence of exploitation dating back to April 2026. Organizations are urged to apply the available hotfixes immediately to mitigate risks.
Key Points: • CVE-2026-16232 allows unauthenticated access to Check Point SmartConsole with full admin rights. • The vulnerability has a CVSS score of 9.3 and is actively exploited in the wild. • CISA has mandated a patch deadline of July 25, 2026, for affected organizations.